Known vulnerabilities in Hello Plus
Hello+ is a free WordPress plugin designed to work seamlessly with Elementor’s Hello suite of themes.
1Reported vulnerabilities
5.4Highest CVSS score
1.7.8Latest version
70,000+Active installs
What to do now
Update Hello Plus to 1.7.8 or later.
1 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-5727 | Medium | — | 1.7.7 and earlier | 1.7.8 |
October 9, 2026 |